VendorsAruba Networkssd-wanall versions
Vulnerabilities

Aruba Networks Arubanetworks SD-WAN

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

98CVEs
CVE-2020-24633
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
10.0EPSS 0.051
CVE-2021-37716
A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
10.0EPSS 0.024
CVE-2020-24634
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
10.0EPSS 0.021
CVE-2024-26305
There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-01 · Analyzed
9.8EPSS 0.152
CVE-2022-37897
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
9.8EPSS 0.018
CVE-2023-22747
Multiple Unauthenticated Command Injections in the PAPI Protocol
Published 2023-02-28 · Modified
9.8EPSS 0.017
CVE-2023-22748
Multiple Unauthenticated Command Injections in the PAPI Protocol
Published 2023-02-28 · Modified
9.8EPSS 0.017
CVE-2023-22749
Multiple Unauthenticated Command Injections in the PAPI Protocol
Published 2023-02-28 · Modified
9.8EPSS 0.017
CVE-2023-22750
Multiple Unauthenticated Command Injections in the PAPI Protocol
Published 2023-02-28 · Modified
9.8EPSS 0.017
CVE-2023-22751
Unauthenticated Stack-Based Buffer Overflow Vulnerabilities in the PAPI Protocol
Published 2023-02-28 · Modified
9.8EPSS 0.013
CVE-2023-22752
Unauthenticated Stack-Based Buffer Overflow Vulnerabilities in the PAPI Protocol
Published 2023-02-28 · Modified
9.8EPSS 0.013
CVE-2023-22753
Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
Published 2023-02-28 · Modified
9.8EPSS 0.011
CVE-2023-22756
Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
Published 2023-02-28 · Modified
9.8EPSS 0.011
CVE-2023-22754
Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
Published 2023-02-28 · Modified
9.8EPSS 0.011
CVE-2023-22757
Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
Published 2023-02-28 · Modified
9.8EPSS 0.011
CVE-2023-22755
Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
Published 2023-02-28 · Modified
9.8EPSS 0.011
CVE-2021-37720
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37721
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37717
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37718
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37722
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37719
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.029
CVE-2020-24637
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or modified kernel in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
9.0EPSS 0.016
CVE-2022-37912
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.016
CVE-2026-44871
Authenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
8.8EPSS 0.012
CVE-2026-44866
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.009
CVE-2026-44870
Authenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
8.8EPSS 0.009
CVE-2026-44868
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.009
CVE-2026-44867
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.009
CVE-2026-44869
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.009
CVE-2022-37905
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.008
CVE-2022-37903
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.008
CVE-2022-37904
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.007
CVE-2023-35971
Unauthenticated Stored Cross-Site Scripting (XSS) in ArubaOS Web-based Management Interface
Published 2023-07-05 · Modified
8.8EPSS 0.006
CVE-2021-37725
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
8.8EPSS 0.004
CVE-2022-37906
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.
Published 2022-11-03 · Modified
8.1EPSS 0.008
CVE-2023-35975
Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion
Published 2023-07-05 · Modified
8.1EPSS 0.007
CVE-2023-35979
Unauthenticated Buffer Overflow Vulnerability in ArubaOS Web-Based Management Interface
Published 2023-07-05 · Modified
7.5EPSS 0.006
CVE-2022-37907
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller.
Published 2022-11-03 · Modified
7.5EPSS 0.006
CVE-2026-23827
Unauthenticated Remote Code Execution via Heap Buffer Overflow in Network Management Service
Published 2026-05-12 · Analyzed
7.5EPSS 0.005
1 / 3Next →